Critical WordPress Flaw Being Actively Exploited: Update Now

A serious security flaw in the heart of WordPress is being exploited by attackers right now. If you run a WordPress website, for your business, your clients, or any other purpose, you need to check whether it has been updated, and check it today.

What has happened

Researchers discovered and published details of a critical vulnerability chain in WordPress Core in July 2026. Given the nickname “wp2shell” by the security community, it allows a completely unauthenticated attacker, someone with no account on your site and no special access, to execute their own code directly on your web server.

The attack works by chaining two flaws together. The first (CVE-2026-63030) exploits a confusion in how WordPress’s REST API routes incoming requests. The REST API is the behind-the-scenes interface that WordPress uses to serve data to apps, mobile integrations, and the block editor, it is active on virtually every modern WordPress site by default. The second flaw (CVE-2026-60137) exploits that confusion to inject malicious database commands. Together, the two allow an attacker to take full control of the server without logging in, without needing any plugins installed, and without any special configuration on the target site.

WordPress released security patches on 17 July 2026. The affected versions are 6.9.0 through 6.9.4 and 7.0.0 through 7.0.1. The fixed releases are 6.9.5, 7.0.2, and 6.8.6 for sites on the older branch.

Why this matters to your business

Active exploitation was confirmed by multiple independent security vendors within days of the patch being published. Attackers are using wp2shell to plant “webshells” on vulnerable websites. A webshell is a hidden back-door script that gives an attacker persistent, ongoing access to the server even after the underlying vulnerability is fixed – like a key cut from a broken lock.

Once a webshell is in place, an attacker can:

  • Read or steal everything on the web server, including contact form submissions, customer records, files, and database contents
  • Redirect your visitors to phishing pages or malware downloads without your knowledge
  • Deface the site with unwanted content, or hold it to ransom
  • Use your server as a launch pad for attacks on other systems

For UK businesses, a compromised website that leaks personal data carries obligations under the UK GDPR, including potential notification to the Information Commissioner’s Office (ICO), as well as serious reputational damage. Google also flags sites that distribute malware and can remove them from search results entirely, often with very little warning.

What we have done for SFIT-managed websites

For every client whose WordPress website we manage as part of our managed IT services, we have reviewed and updated WordPress Core to a patched version and checked server logs for any indication of compromise. If you are an SFIT client and have any concerns, please call us directly.

What to do if you manage your own WordPress site

1. Check your WordPress version now. Log in to your WordPress dashboard and go to Dashboard > Updates. If a WordPress Core update is available, apply it immediately. You should be on version 6.9.5, 7.0.2, or 6.8.6 depending on which branch your site runs.

2. Do not assume auto-update handled it. WordPress.org pushed automatic updates to many sites affected by this vulnerability — but sites running heavily customised themes or complex plugin configurations sometimes have auto-updates disabled to avoid compatibility issues. Verify manually rather than assuming.

3. If your site was running a vulnerable version before you updated, treat it as potentially compromised. Look for unknown administrator accounts, unfamiliar files in the uploads or themes directories, and any unexpected changes to your .htaccess file. A free “Compromise Scanner for wp2shell” tool is listed in the WordPress plugin directory and may assist with an initial check.

4. Speak to your hosting provider. Managed WordPress hosts (such as WP Engine, Kinsta, or SiteGround) should have updated and scanned hosted sites automatically, but confirm this rather than assuming. Ask them directly.

5. Check your backups. If you do not have clean, tested backups of your site and database taken from before any potential compromise, address this now. Restoring from a clean backup is often the most reliable way to recover from a webshell infection, partial clean-ups frequently miss secondary back-doors.

A note on clean-up

WordPress compromises can be difficult to fully remediate. Webshells are often concealed in unexpected locations, and attackers frequently plant multiple back-doors to maintain access even after an initial clean-up. If you have any concern that your site may have been affected, particularly if you were running a vulnerable version for a period after 17 July, the safest approach is to have a specialist examine it properly rather than attempting a self-clean.

Our IT security team carries out website security reviews and can check for signs of compromise. We also provide IT support and maintenance services that include regular patching and security monitoring so situations like this are caught and handled before they become a problem for your business.

If you would like help checking or securing your WordPress site, get in touch or call 01452 701355 for a no-obligation chat. You can also contact us online and we will get back to you promptly.

Stay one step ahead of the threats

Get our free weekly IT and cyber security briefing for UK businesses. The same threat and policy round-up we send our own clients, straight to your inbox. No spam, unsubscribe any time.

Get the free weekly briefing →

Table of Contents

Would you like to know how we can help?

Get in touch

Name